sorry for the delay. here is the combofix log.
ComboFix 08-07-03.5 - USER 2008-07-08 1:24:42.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.490 [GMT -7:00]
Running from: C:\Documents and Settings\USER\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\USER\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\regxpcom.exe
C:\WINDOWS\system32\{41957f54-8c2c-de81-f2a7-893c69fd2cf2}.dll
C:\WINDOWS\system32\drivers\evolusb.sy
C:\WINDOWS\system32\pinkip.ico
C:\windows\system32\rwwnw64d.exe
C:\WINDOWS\system32\sgeqbfmj.dll
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\system32\xdulewds.VIR
C:\WINDOWS\VVNFUg\pphIo0.vbs
E:\maple story\npkycryp.sy
C:\Documents and Settings\ShoppingReport :#:
C:\Documents and Settings\report :#:
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Avira
C:\Program Files\BoontyGames
C:\regxpcom.exe
C:\TEMP\syschk3
C:\TEMP\syschk3\tdirp5.log
C:\WINDOWS\system32\bam
C:\WINDOWS\system32\modtrux18
C:\WINDOWS\system32\modtrux18\modtrux182328.exe
C:\WINDOWS\system32\mp
C:\WINDOWS\system32\mp\dvsid140.exe
C:\WINDOWS\system32\pinkip.ico
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\system32\vec3
C:\WINDOWS\system32\vec3\wesamdir.exe
C:\WINDOWS\system32\xdulewds.VIR
C:\WINDOWS\system32\xsir
C:\WINDOWS\system32\xsir\dragGLL1.exe
C:\WINDOWS\VVNFUg
C:\WINDOWS\VVNFUg\pphIo0.vbs
.
((((((((((((((((((((((((( Files Created from 2008-06-08 to 2008-07-08 )))))))))))))))))))))))))))))))
.
2008-07-03 13:10 . 2008-07-03 13:13 <DIR> d-------- C:\WINDOWS\SrInstallTemp
2008-07-03 13:10 . 2008-07-03 13:13 <DIR> d-------- C:\Program Files\Sr
2008-07-02 13:33 . 2005-02-02 01:41 67,456 --a------ C:\WINDOWS\system32\drivers\pavdrv51.sys
2008-07-02 13:33 . 2002-10-09 06:08 95 --a------ C:\WINDOWS\msje8tp.dat
2008-07-02 13:32 . 2008-07-02 13:32 <DIR> d-------- C:\Upload
2008-07-02 13:32 . 2008-07-02 13:32 <DIR> d-------- C:\ReplaceOnReboot
2008-07-02 13:32 . 2008-07-02 13:32 0 --a------ C:\WINDOWS\system32\lockscr.dat
2008-07-02 13:28 . 2002-10-08 16:08 290,816 --a------ C:\WINDOWS\system32\WINHTTP5.DLL
2008-06-30 21:17 . 2008-06-30 21:17 <DIR> d-------- C:\Documents and Settings\ShoppingReport
2008-06-30 21:17 . 2008-06-30 21:17 <DIR> d-------- C:\Documents and Settings\report
2008-06-30 19:45 . 2008-06-30 19:46 63,918 --a------ C:\WINDOWS\system32\{41957f54-8c2c-de81-f2a7-893c69fd2cf2}.dll-uninst.exe
2008-06-29 23:03 . 2007-08-01 23:47 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-29 19:49 . 2008-06-29 19:50 <DIR> d-------- C:\Program Files\FBrowserAdvisor
2008-06-29 19:49 . 2008-07-03 14:03 <DIR> d-------- C:\Program Files\AdvancedAdvisor
2008-06-16 21:54 . 2008-06-29 22:47 <DIR> d-------- C:\Program Files\Fx Video Converter
2008-06-16 21:54 . 2001-03-13 12:50 525,352 --a------ C:\WINDOWS\system32\dbgrid32.ocx
2008-06-16 21:54 . 2001-08-17 12:18 508,928 --a------ C:\WINDOWS\system32\msde.dll
2008-06-16 21:54 . 1999-02-16 20:49 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2008-06-16 21:54 . 2003-05-21 23:50 156,910 --a------ C:\WINDOWS\WMSysPr8.prx
2008-06-16 21:54 . 2001-03-13 12:53 77,824 --a------ C:\WINDOWS\system32\msbind.dll
2008-06-16 21:54 . 2000-06-13 00:00 2,493 --a------ C:\WINDOWS\system32\COMCTL32.DEP
2008-06-16 21:53 . 2008-06-16 21:53 <DIR> d-------- C:\Program Files\Common Files\Download Manager
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-06 03:00 --------- d-----w C:\Program Files\QuickTime
2008-07-06 03:00 --------- d-----w C:\Program Files\ltmoh
2008-07-04 00:41 --------- d-----w C:\Documents and Settings\USER\Application Data\iolo
2008-07-03 21:21 --------- d-----w C:\Program Files\iolo
2008-07-03 21:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\iolo
2008-06-30 08:46 --------- d-----w C:\Documents and Settings\USER\Application Data\LimeWire
2008-06-17 02:21 29,696 ----a-w C:\WINDOWS\system32\iolobtdfg.exe
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-06 23:55 8,704 ----a-w C:\WINDOWS\system32\smrgdf.exe
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 06:16 --------- d-----w C:\Program Files\My Downloaded Games
2008-05-08 06:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-05-08 06:15 --------- d-----w C:\Program Files\Free Offers from Freeze.com
2008-05-08 06:15 --------- d-----w C:\Program Files\AWS
2008-05-08 06:15 --------- d-----w C:\Documents and Settings\USER\Application Data\WeatherBug
2008-05-08 06:12 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-06 23:36 428,904 ----a-w C:\WINDOWS\system32\Incinerator.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((( snapshot@2008-07-05_ 6.28.05.01 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-05 13:23:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-08 06:54:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 13,312 2003-03-31 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-04 07:56:48 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 15:21 198184]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 7\SMSystemAnalyzer.exe" [N/A]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 14:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\agrsmmsg.exe]
"TPSMain"="TPSMain.exe" [2004-03-03 12:57 278528 C:\WINDOWS\system32\TPSMain.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2004-05-07 11:54:09 155648]
Wireless Configuration Utility HW.15.lnk - C:\Program Files\TRENDnet\TRENDnet TEW-421PC_TEW-423PI\WlanCU.exe [2007-01-30 14:57:42 577536]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Toshiba\\Windows Utilities\\TACSPROP.exe"=
R0 atiide;atiide;C:\WINDOWS\system32\DRIVERS\atiide.sys [2004-04-14 14:52]
R2 ioloFileInfoList;iolo FileInfoList Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-06-19 16:59]
R2 ioloSystemService;iolo System Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-06-19 16:59]
R2 NwSapAgent;SAP Agent;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
R2 SR Agent;Secure Resolutions Managed Agent;C:\Program Files\Sr\AgentSvc.exe [2005-07-16 21:13]
R3 odysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys [2004-09-24 23:36]
S3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\System32\CBTNDIS5.SYS [2003-07-16 22:28]
S3 EVOLUSB;%EVOL_USB_SvcDesc%;C:\WINDOWS\system32\drivers\evolusb.sys []
S3 npkycryp;npkycryp;E:\maple story\npkycryp.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5f97f56-94bd-11dc-a167-0014d134f3b7}]
\Shell\Auto\command - E:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-08 01:28:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-07-08 1:30:27
ComboFix-quarantined-files.txt 2008-07-08 08:30:20
ComboFix2.txt 2008-07-05 13:28:37
Pre-Run: 5,567,348,736 bytes free
Post-Run: 5,631,623,168 bytes free
163 --- E O F --- 2008-06-20 16:20:44